Skip to content
Apple zero-day, Microsoft mega-patch (974 CVEs), ShinyHunters Oracle escalation

Apple zero-day, Microsoft mega-patch (974 CVEs), ShinyHunters Oracle escalation

Defendwork •defend.network • September 29, 2026

Apple patched a CoreGraphics zero-day possibly exploited in targeted attacks; Microsoft issued its largest patch batch ever (974 vulnerabilities); ShinyHunters escalated attacks after a member's arrest in the Netherlands, now exploiting Oracle PeopleSoft workarounds.

Apple released security updates for CVE-2026-86950, a CoreGraphics out-of-bounds write in iOS, iPadOS, and macOS that may have been exploited in targeted attacks.

Microsoft published its largest security update ever, addressing at least 974 vulnerabilities across Windows and other products, with AI cited as a discovery accelerant.

ShinyHunters hacking group escalated attacks after a 23–24 year old member's arrest in Amsterdam, now using modified exploits against Oracle PeopleSoft vulnerability CVE-2026-35273 .

Cryptocurrency exchange Bitget confirmed a $388 million theft exploited a third-party security product vulnerability, not an exchange platform flaw.

Misconfigured Supabase databases exposed over 16,000 instances containing PII, passwords, and authentication tokens.

1. Apple CoreGraphics Zero-Day Possibly Exploited

Severity: HIGH Affected: Technology

Apple has released security updates to address CVE-2026-86950, an out-of-bounds write vulnerability in the CoreGraphics component affecting older versions of iOS, iPadOS, and macOS [1] . The company stated the flaw may have been exploited in targeted attacks [1] . Specific version numbers and patch details were not disclosed in available reports. Sources: [1] The Hacker News

Prioritize updates to iOS, iPadOS, and macOS devices, particularly in organizations managing high-value targets

Monitor endpoints for suspicious CoreGraphics-related process behavior or memory corruption crashes

Review logs for any indicators of targeted attack activity on Apple platforms

2. Microsoft Patches Record 974 Vulnerabilities

Severity: HIGH Affected: Technology

Microsoft Corp. issued updates to plug at least 974 security holes in Windows operating systems and other software, representing its largest single patch batch ever [1] . The company cited artificial intelligence as a tool helping to speed vulnerability discovery, though security experts warn many of the newly patched flaws may have been unknown to defenders until now [1] . Sources: [1] Krebs on Security

Establish an expedited testing and deployment schedule for the Microsoft patch batch

Prioritize Windows systems and commonly-targeted Microsoft products (Office, Exchange, Edge)

Verify patch applicability to your environment and test in isolated infrastructure before broad deployment

3. ShinyHunters Escalate Attacks on Oracle PeopleSoft After Member Arrest

Severity: HIGH Affected: Technology

Dutch police arrested a 23–24 year old convicted cybercriminal in connection with the prolific ShinyHunters hacking group; in the days following the arrest, remaining ⚠ ShinyHunters members dramatically escalated their attack activity [1] . The group is now exploiting CVE-2026-35273, a vulnerability in Oracle PeopleSoft, using modified exploits in targeted campaigns [2] [3] . Mandiant researchers and Google have both warned of this escalating activity [2] [3] . Sources: [1] Krebs on Security [2] The Record [3] SecurityWeek

Audit Oracle PeopleSoft instances for unauthorized access and patch CVE-2026-35273 immediately

Review authentication logs for brute-force attempts or unusual credential usage against PeopleSoft systems

Monitor for data exfiltration from HR, payroll, and financial modules targeted by ShinyHunters in prior campaigns

4. Bitget Cryptocurrency Exchange Loses $388M via Third-Party Security Product Flaw

Severity: HIGH Affected: Finance

Bitget cryptocurrency exchange disclosed a theft of approximately $388 million; the attacker exploited a vulnerability in a third-party security product used by the exchange to obtain high-level internal credentials [1] . On September 24, the attacker used those credentials to access and drain cryptocurrency holdings ⚠ [1] . This incident highlights supply-chain risks in security tooling itself. Sources: [1] The Hacker News

Audit all third-party security products and admin tools for known vulnerabilities and credential exposure

Implement privileged access management (PAM) to limit exposure of high-level internal credentials

Review transaction logs and withdrawal activity for anomalies in the 30 days prior to and following September 24, 2026

5. Over 16,000 Supabase Databases Misconfigured, Exposing Credentials and PII

Severity: HIGH Affected: Technology

Researchers discovered more than 16,000 misconfigured Supabase databases exposing readable tables containing personally identifiable information, passwords, and authentication tokens [1] . Supabase is a widely-used backend-as-a-service platform; the scale of exposure indicates systematic configuration errors across a large developer base. Sources: [1] BleepingComputer

If you operate Supabase instances, immediately verify row-level security (RLS) policies are enabled and correctly configured

Rotate any credentials or API keys that may have been exposed through misconfigured databases

Audit recent access logs for unauthorized data access attempts

Citrix NetScaler CVEs: Earlier coverage of CVE-2026-88771 and CVE-2026-88772 remains current; both are now in CISA's Known Exploited Vulnerabilities catalog with federal remediation deadline 2026-09-30 [31, 32].

NeedyMantis Malware: Microsoft reports the NeedyMantis malware family is being used to maintain long-term access in targeted intrusions at telecommunications, university, and medical nonprofit organizations [2].

RatHat Android Banking Trojan: Cleafy reports the RatHat Android banking trojan malware-as-a-service model, with nearly 100 deployed command consoles traced since April 2026 and operators using AI (Gemini) to identify higher-value victims [5].

JadePuffer Agentic Ransomware on Azure: JadePuffer ransomware operators are conducting agent-driven attacks against Azure tenants, performing reconnaissance, stealing credentials, and destroying cloud resources [10].

Arrests & Sentencing: Dutch police confirmed a 24-year-old Amsterdam resident arrested in connection with ShinyHunters [8]. A U.S. Army soldier was sentenced to 70 months in federal prison for hacking AT&T, Verizon, and other telecom companies, stealing call and text metadata for over 100 million AT&T customers [12].

Today’s Action Checklist

☐ URGENT: Deploy Microsoft's 974-vulnerability patch batch to Windows and Microsoft products on an expedited timeline

☐ URGENT: Audit Oracle PeopleSoft systems for CVE-2026-35273 and apply patches; review authentication and data access logs

☐ Update iOS, iPadOS, and macOS to latest versions addressing CVE-2026-86950

☐ If using Supabase, verify row-level security policies are enabled and audit for unauthorized access

☐ Review third-party security tools and admin credentials for exposure; implement privileged access management controls